Researchers disclosed a technique that bypassed Microsoft’s Control Flow Guard (CFG) in Internet Explorer and Edge by abusing the Chakra JavaScript engine’s JIT compilation process. The method assumed an attacker already had a read-write memory primitive, then located Chakra’s temporary JIT native-code buffer, altered the generated code before it was copied into executable memory, and executed the modified result without directly violating CFG’s indirect-call protections.
Microsoft’s CFG is designed to restrict calls to valid control-flow targets in Win32 applications, but the reported bypass showed that JIT-generated code could be tampered with before finalization and still become an approved execution target. The technique was reported through Microsoft’s mitigation bypass bounty program, demonstrated against Internet Explorer 11 on Windows 10, and later addressed in MS16-119 and ChakraCore updates that added checksum validation before marking JIT entry points as valid CFG targets.

Get the actors, campaigns, and ATT&CK mapping behind it.
3 events from the most recent confirmed update back to the earliest known activity.
Microsoft later fixed the reported Chakra JIT Control Flow Guard bypass in security update MS16-119. ChakraCore was also changed to add checksum validation before marking JIT entry points as valid CFG targets.
Theori reported a technique for bypassing Microsoft Control Flow Guard in Internet Explorer and Edge through Microsoft's mitigation bypass bounty program. The bypass abused Chakra's temporary JIT encode buffer to alter native code before it was finalized as an executable CFG target.
Theori publicly disclosed technical details of the Chakra JIT CFG bypass and said it had demonstrated the technique against Internet Explorer 11 on Windows 10 using an adapted proof-of-concept exploit. The blog post explained how an attacker with a read-write memory primitive could tamper with JIT-generated code before it was copied into executable memory.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.